F5 BIG-IP Container Ingress Services
cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.20.1
- >= 1.0.0, <= 1.14.0
A vulnerability in F5 BIG-IP Container Ingress Services for Kubernetes and OpenShift, specifically in versions 2.0.0 through 2.20.1 and 1.0.0 through 1.14.0, may grant excessive permissions to read cluster secrets. This issue affects the control plane only, with no exposure on the data plane.
A remote, authenticated attacker with high privilege access to BIG-IP Container Ingress Services could read cluster secrets, potentially leading to unauthorized access or manipulation of sensitive information within the cluster.
Users can upgrade to BIG-IP Container Ingress Services versions 2.20.2 or 1.14.1 to address this vulnerability. For version 2.20.1, Helm version 0.0.36 can be used to install the update. To mitigate the vulnerability without upgrading, permissions can be narrowed down to specific resources and namespaces as needed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.